Junglewise Threat Intelligence

CVE-2026-68777: Microsoft SQL Server out-of-bounds read information disclosure

CVE-2026-68777 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Technologies: Microsoft SQL Server. Vendors: Microsoft.

Executive brief

SQL Server is a database management system used by organizations to store and manage critical business data. This vulnerability allows an authorized user to read sensitive information from memory that should not be accessible, potentially exposing confidential data across the network.

Technical details

An out-of-bounds read vulnerability exists in Microsoft SQL Server that enables information disclosure. The vulnerability requires authentication and network access to exploit. An attacker with valid SQL Server credentials can trigger the out-of-bounds read to access and exfiltrate sensitive data from server memory. The attack vector is network-based and does not require elevated privileges beyond standard database access.

Affected products

  • Microsoft SQL Server

Timeline

  • 2026-09-08: disclosed

References

Related threats